
A Decade-Old Driver Disguise Still Fools Two-Thirds of Antivirus
A resurfacing trojan masquerades internally as Windows' partmgr.sys driver while using randomized external filenames and no code-signing certificate. Only one of two new file hashes in this batch yields usable evidence; the other returns no retrievable data, leaving a single sample to carry the entire update.
A trojan now resurfacing in a fresh indicator batch presents itself internally as c:\windows\system32\drivers\partmgr.sys — the Windows partition-manager driver — while the file that actually lands on disk carries a randomized name such as 7PLZfYlw8lxGk5pe1evjS.exe or N06A1Oj5m5fsNFiBO.exe. It ships with no code-signing certificate at all.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read